Your password is the only key. It never leaves this device — the server stores only ciphertext. If you forget it, the files are unrecoverable. There is no reset.
The key is derived here, in your browser. The server only sees a proof you know the password, never the password or the key itself.